Cyber Security Agency of Singapore

csa.gov.sg

Imported from official source

Government body in Singapore; cybersecurity publications from its own official source.

Type
Government
Scope
SG · national
Website
csa.gov.sg
Feed
Atom

Publications 25

  1. Active Exploitation of Vulnerability in Roundcube Webmail

    Attackers are exploiting a high-severity vulnerability in Roundcube Webmail to perform SQL injection without authentication. Patch immediately.

    Announcement
  2. Security Bulletin 30 Sept 2026 [PDF, 1 MB]

    Announcement 1 document
  3. Advisory on CARBONATO Botnet Campaign Targeting Exposed Docker Daemons

    Security researchers have identified a botnet campaign known as CARBONATO targeting Docker hosts with unauthenticated Docker Remote APIs exposed to the Internet. Organisations operating Docker envi...

    Announcement
  4. High-Severity Vulnerability in Apple Products

    Attackers can exploit a high-severity vulnerability in Apple products to execute arbitrary code on affected devices. Patch immediately.

    Announcement
  5. Active Exploitation of Vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway

    Attackers are exploiting multiple vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway. Patch immediately.

    Announcement
  6. Active Exploitation of High-Severity Vulnerability in WordPress

    Attackers are exploiting a high-severity vulnerability in WordPress to achieve remote code execution under specific conditions. Patch immediately.

    Announcement
  7. Multiple Vulnerabilities in Synology DiskStation Manager (DSM)

    Attackers can exploit multiple vulnerabilities in Synology DiskStation Manager (DSM) to read or write arbitrary files and conduct denial-of-service attacks. Patch immediately.

    Announcement
  8. Active Exploitation of Vulnerability in Cisco Identity Services Engine

    Attackers are exploiting a critical vulnerability in Cisco Identity Services Engine and Cisco Identity Services Engine Passive Identity Connector to bypass authentication and gain unauthorised acce...

    Announcement
  9. Active Exploitation of Critical Vulnerability in Cisco AsyncOS

    Attackers are exploiting a critical vulnerability in Cisco AsyncOS to execute arbitrary commands with root privileges. Patch immediately.

    Announcement
  10. Active Exploitation of Critical Vulnerability in GitLab

    Attackers are exploiting a critical vulnerability in GitLab to read arbitrary files from the server. Patch immediately.

    Announcement
  11. Active Exploitation of Vulnerability in Vite Development Servers

    Attackers are exploiting a high severity vulnerability in Vite development servers to retrieve restricted system and configuration files over HTTP. Patch immediately.

    Announcement
  12. Security Bulletin 16 Sep 2026 [PDF, 2MB]

    Announcement 1 document
  13. High-Severity Vulnerability in MongoDB Server

    Attackers can exploit a high-severity vulnerability in MongoDB Server to gain full unauthenticated administrative access to the affected database. Patch promptly.

    Announcement
  14. Critical Vulnerabilities in Check Point Quantum Security Gateway and Security Management Server

    Attackers can exploit critical vulnerabilities in Check Point Quantum Security Gateway and Security Management Server to perform remote code execution without authentication. Patch immediately.

    Announcement
  15. September 2026 Monthly Patch

    Microsoft has released security patches to address multiple vulnerabilities in their software and products.

    Announcement
  16. Active Exploitation of Vulnerability in N-Able N-Central

    Attackers are exploiting a critical vulnerability in N-Able N-Central remote management and monitoring tool to execute code remotely without authentication. Patch immediately.

    Announcement
  17. Active Exploitation of Vulnerability in Adobe Products

    Attackers are exploiting a critical vulnerability in Adobe Commerce, Adobe Commerce B2B and Adobe Magento to execute arbitrary code. Patch immediately.

    Announcement
  18. Critical Vulnerabilities in SAP Products

    Attackers can exploit multiple vulnerabilities in SAP Products to execute arbitrary commands, obtain sensitive credentials, replace or delete tenant data and perform unauthorised actions. Patch imm...

    Announcement
  19. High-Severity Vulnerability in PostgreSQL

    Attackers can exploit a high-severity vulnerability in PostgreSQL to execute arbitrary code on the affected system. Patch promptly.

    Announcement
  20. Active Exploitation of Vulnerability in NetScaler ADC and NetScaler Gateway

    Attackers are exploiting a critical vulnerability in NetScaler ADC and NetScaler Gateway. Patch immediately.

    Announcement
  21. Active Exploitation of Vulnerabilities in SonicWall SMA1000 Series

    Attackers are exploiting vulnerabilities in SonicWall SMA1000 Series appliances to gain unauthorised access to sensitive functionalities and execute arbitrary operating system (OS) commands.

    Announcement
  22. Security Bulletin 2 Sept 2026 [PDF, 2MB]

    Announcement 1 document
  23. Active Exploitation of Vulnerabilities in Microsoft SharePoint

    Attackers are exploiting multiple vulnerabilities in Microsoft SharePoint Server to bypass a security feature and run code over a network. Patch immediately.

    Announcement

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.